A firewall is a network security control that monitors and filters incoming and outgoing traffic according to a defined rule set, allowing or blocking packets and connections to enforce a security boundary. Firewalls range from stateless packet filters to stateful inspection devices and next-generation appliances that perform deep packet inspection and application awareness. They are a foundational component for segmenting trusted and untrusted networks.

Overview

  • Firewalls inspect traffic at the perimeter or between internal zones and decide, per packet or per connection, whether it conforms to policy.
  • They evolved from simple packet filters to stateful inspection, which tracks connection state, and to next-generation firewalls that understand applications and users.
  • Firewalls are deployed as dedicated hardware, virtual appliances or host-based software.

Key aspects

  • Packet filtering on addresses, ports and protocols.
  • Stateful inspection that correlates packets to established sessions.
  • Deep packet inspection and application-layer awareness in next-generation devices.
  • Integration with VPN termination, logging and threat intelligence feeds.

Applications

  • Perimeter defence between an organisation and the public internet.
  • Internal Network Segmentation to contain lateral movement.
  • Host-based protection on servers and endpoints.
  • Cloud security groups and virtual firewalls in Cybersecurity architectures.

Provenance